Intrusion Prevention

Schneider.Electric.ClearSCADA.HTTP.Interface.XSS

Description

This indicates an attack attempt to exploit a Denial Of Service vulnerability in Schneider Electric SCADA Expert ClearSCADA.
The vulnerability is due to an error in the application when handling incoming requests. An attacker can exploit this by tricking an unsuspecting user into visiting a malicious webpage and uses his/her privilege to send a request which may causes denial of service conditions in the affected machine.

Affected Products

Schneider Electric ClearSCADA 2010 prior to R3.2
Schneider Electric SCADA Expert ClearSCADA 2014 prior to R1.1

Impact

Denial of Service: Remote attackers can crash vulnerable systems.

Recommended Actions

Apply the most recent upgrade or patch from the vendor
http://resourcecenter.controlmicrosystems.com/display/public/CS/SCADA+Expert+ClearSCADA+Support

CVE References

CVE-2014-5411